Web, Mobile, API, Cloud & Infrastructure | U.S.-Based
About the Opportunity
At TechCompass, penetration testing is about more than producing a list of vulnerabilities.
Our testers simulate realistic attack paths, validate whether weaknesses can actually be exploited, determine potential business impact, and give clients clear guidance on what needs to change.
We work with organizations at different stages of security maturity, from growing technology companies to established businesses with complex environments. Engagements vary, which means our testers need technical depth, curiosity, sound judgment, and the ability to communicate clearly with clients.
This is an evergreen opportunity. We’re always interested in connecting with experienced U.S.-based penetration testers as our team and client needs grow.
What You'll Do
Depending on your specialization and the engagement, you may:
- Scope and perform authorized penetration tests against web applications, APIs, mobile applications, cloud environments, internal networks, external attack surfaces, or other systems.
- Combine automated tooling with hands-on manual testing and exploitation techniques.
- Identify vulnerabilities, insecure configurations, broken access controls, authentication weaknesses, privilege escalation paths, and other exploitable conditions.
- Evaluate how individual weaknesses could be combined into realistic attack paths.
- Validate findings to distinguish meaningful risk from scanner noise and false positives.
- Document testing methodology, evidence, exploitation paths, affected assets, and potential business impact.
- Develop clear remediation guidance that technical teams can act on.
- Prepare professional client-facing penetration testing reports.
- Walk clients through findings and answer questions from technical teams, security leaders, and business stakeholders.
- Perform retesting to validate remediation when required.
- Stay current on emerging vulnerabilities, attack techniques, tooling, and changes across modern application and cloud environments.
- Collaborate with other TechCompass security practitioners when penetration testing is part of a broader security engagement.
What We're Looking For
Strong candidates will typically bring:
- Approximately 3–5+ years of professional penetration testing, offensive security, application security, security consulting, or closely related experience.
- Demonstrated experience performing hands-on security testing, not solely vulnerability scanning.
- Strong understanding of common attack techniques, vulnerability classes, and exploitation methodologies.
- Experience documenting findings and producing professional technical reports.
- The ability to explain vulnerabilities, attack paths, business impact, and remediation clearly.
- Familiarity with established testing methodologies and resources such as OWASP, PTES, MITRE ATT&CK, or similar frameworks.
- Experience with common offensive-security and testing tools appropriate to your area of specialization.
- Strong problem-solving skills and the ability to work independently within an agreed scope and rules of engagement.
- A high standard of professionalism, discretion, and ethical conduct.
- U.S.-based work authorization and residence.
Specialization Is Welcome
We are not expecting every penetration tester to be an expert across every technology.
We are interested in candidates with strong capabilities in one or more of the following:
Web Application & API Testing
- Web application security testing
- API security and authorization testing
- Authentication and session management
- Business logic vulnerabilities
- OWASP Top 10 and related application attack techniques
Mobile Application Testing
- iOS and/or Android security testing
- Mobile application data storage and communications
- Authentication and authorization
- API interaction and backend testing
- Mobile-specific attack techniques
Cloud Penetration Testing
- AWS, Azure, and/or GCP
- IAM and privilege escalation
- Cloud misconfiguration exploitation
- Storage, compute, serverless, container, and network security
- Lateral movement and attack-path analysis within cloud environments
Network & Infrastructure Testing
- Internal and external penetration testing
- Active Directory and identity-based attacks
- Privilege escalation
- Lateral movement
- Network services, segmentation, and attack-surface testing
Experience with additional areas such as source-code review, wireless testing, social engineering, red teaming, container security, Kubernetes, or emerging technologies is also valuable.
Tools & Technical Knowledge
Depending on your specialization, your experience may include tools and technologies such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, cloud-native security tooling, scripting languages, mobile testing frameworks, or other offensive-security platforms.
We don’t hire based on a tool checklist. We’re more interested in whether you understand why a vulnerability exists, how to validate it safely, what an attacker could realistically do with it, and how the client should address it.
Certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, PNPT, or similar credentials are valued but are not a substitute for practical experience.
What Makes a Great TechCompass Tester
The best penetration testers for our team aren’t just technically capable.
They can move from:
“I found a vulnerability.”
to:
“Here’s how an attacker could use it, what it puts at risk, how serious it is in this environment, and what you should do next.”
That ability to connect technical findings to real-world risk is central to how TechCompass works with clients.
Why TechCompass
TechCompass is a boutique cybersecurity firm focused on expert-led, practical security work.
Our broader team works across assessments, cloud and product security, security program development, compliance, security engineering, and strategic advisory, giving penetration testers the opportunity to see how offensive-security findings fit into a client’s larger security program.
You’ll work across varied environments and meaningful security challenges alongside experienced practitioners who value technical depth, clear communication, and work clients can actually use.
Interested in Working With TechCompass?
Whether your specialty is web applications, mobile, APIs, cloud, infrastructure, or a combination, we’d like to hear from you.
Tell us where you’re strongest, the types of environments you’ve tested, and the kind of offensive-security work you want to take on next.
Submit your application to be considered for current and future opportunities with TechCompass.